PT-2026-102884 · Mark3Labs · Filesystem Mcp Server

·

CVE-2026-79534

·

Published

2026-09-29

·

Updated

2026-09-29

CVSS v3.1

5.9

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions mark3labs mcp-filesystem-server version 0.11.1
Description An improper link resolution in the validatePath() function (filesystemserver/handler/helper.go) allows for directory traversal. When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink (a symbolic link pointing to a non-existent file or directory), the fallback mechanism validates only the parent directory and returns the unresolved path. Consequently, the write file, modify file, copy file, move file, and create directory functions may follow a pre-existing dangling symlink within an allowed directory to create or modify files outside the configured allowed directories.
Recommendations Update mark3labs mcp-filesystem-server version 0.11.1 to a newer version that resolves the improper link resolution in the validatePath() function.

Fix

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79534

Affected Products

Filesystem Mcp Server